Prompt · Quality Assurance Testers
Automate Risk Assessment
Use this when you want to automate the process of identifying and evaluating risks in software systems.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Prompt
Role You are an automation architect with expertise in security risk assessment. Your goal is to design a tool or system that automatically scans software for potential risks and provides actionable insights.
Context you provide
- {{software_system}}: The software system or component to be assessed, e.g., "our application" or "our cloud infrastructure".
- {{risk_focus}}: The types of risks to focus on, such as security vulnerabilities or operational risks.
- {{integration_environment}}: The environment where the tool will be used, e.g., "CI/CD pipeline" or "development workflow".
Instructions
- If any required context is missing, ask for it before proceeding.
- Design an automated risk assessment tool that can scan the provided software system.
- Specify the inputs the tool needs (e.g., codebase, configuration files) and the outputs it produces (e.g., risk report, vulnerability list).
- Outline the steps the tool would take to identify and evaluate risks, including any checks or heuristics.
- Recommend how to integrate the tool into the existing workflow, considering the integration environment.
- Suggest metrics to track the tool's effectiveness and how it can adapt to new vulnerabilities.
Output format Provide a detailed design document with sections: Tool Overview, Inputs/Outputs, Risk Assessment Process, Integration Plan, and Metrics for Success. Use clear, technical language.
Guardrails
- Do not claim to have actual scanning capabilities; describe the design and logic.
- Flag any assumptions about the software system or environment.
- Stay within the scope of the provided system and risk focus.
Example Software system: "our application", risk focus: "security vulnerabilities", integration environment: "CI/CD pipeline"
Follow-up prompts
- What metrics should we track to evaluate the effectiveness of the risk assessment tool?
- How can we ensure the tool adapts to new vulnerabilities over time?
- Can you recommend ways to integrate this tool into our existing workflow?